Mobile payment system with two-point authentication
Abstract
A transaction processing system uses a mobile phone to make payments at point of sale (POS), over the internet, and over the phone, and also to make money transfers. Transaction security is provided by using various combinations of authentication using the mobile phone. Account numbers linked to payment cards, and public/private keys that encrypt/decrypt customer data, dynamically change on mobile phone and a server, based on a specified number of transactions or time interval. No credit/debit account information is shown on mobile phones. GPS location and time stamps facilitate identification of unusual shopping patterns during internet and over-the-phone transactions. Customers can remotely delete data on mobile phone in case of loss. Three-level security used at POS combines industry-standard encryption; dynamically-changing account numbers and keys; and visual identification of customer, followed by software signature recognition.
Claims
exact text as granted — not AI-modified1 : A modular payment system for making payments using a mobile phone, said modular system comprising:
(a) a server; (b) a web site; (c) a mobile phone: (d) a mobile phone application (MPA); (e) a payment-over-phone module (POP); (f) point-of-sale (POS) software; (g) a POS interface device, for processing transactions between the POS software and the server; and (h) a bank interface, for data communication between the server and a bank;
wherein said system is programmed to initiate a payment only after completion of at least two separate user authentication processes, each occurring at a different location.
2 : A modular payment system as in claim 1 wherein the authentication process uses a first dynamic, one-time-use password, generated at a first location.
3 : A modular payment system as in claim 2 wherein the first dynamic password is used in conjunction with a second password, generated at a second location, to encrypt or decrypt user information.
4 : A modular payment system as in claim 3 wherein the second password is a dynamic, one-time-use password.
5 : A modular payment system as in claim 3 wherein the second password is a static, multiple-use password.
6 : A modular payment system as in claim 3 wherein:
(a) the first dynamic password is created manually by a user;
(b) an image representing a random number is automatically generated at the first location and displayed on the mobile phone; and
(c) said first dynamic and said image are used in combination to encrypt user data.
7 : A modular payment system as in claim 5 wherein:
(a) the first dynamic password is created manually by a user;
(b) the first dynamic password and the static password are used in combination to encrypt user data at the second location.
8 : A modular payment system as in claim 5 wherein:
(a) the first dynamic password is created automatically at the first location;
(b) the first dynamic password and the static password are used in combination to encrypt user data at the second location.
9 : A modular payment system as in claim 3 wherein:
(a) the first dynamic password is displayed as a representative image;
(b) a confirmation key corresponding to a random number is created automatically at the first location;
(c) the first dynamic password and the confirmation key are used to encrypt user data; and
(d) encrypted data is electronically transferred from the first location to the second location.
10 : A modular payment system as in claim 9 wherein the first dynamic password is created automatically and displayed as an image at the first location.
11 : A modular payment system as in claim 9 wherein the first dynamic password is created automatically and stored in background at the first location.
12 : A modular payment system as in claim 1 wherein:
(a) a first dynamic password is created manually by a user at a first location;
(b) the first dynamic password and the static password are used in combination to encrypt and decrypt user data at a second location;
(c) the first dynamic key and the confirmation key encrypt data at second location; and
(d) encrypted data is transferred from the second location to the first location.
13 : A modular payment system as in claim 12 wherein:
(a) an unencrypted confirmation number is generated randomly at the first location and then automatically transmitted to the second location;
(b) the unencrypted confirmation number received at the second location is manually re-entered at the first location.Join the waitlist — get patent alerts
Track US2012185398A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.